Centralized Control Plane for Virtual Switch Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of network access control for multiple virtual machines residing on a single physical computer is complicated, as existing technologies lack a centralized and efficient method to coordinate network resources and protocols across virtual machines.

Innovation Solution

A virtual machine monitor (VMM) centralized control plane (CCP) is established, which communicates with multiple VMM data planes to create a single virtual switch across all virtual machines within a cluster of servers, enabling unified network management and packet forwarding, while also handling signaling and control protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple virtual machines are deployed on a single physical computer to maximize hardware utilization, then hardware resource utilization is improved, but network access control management complexity increases

Engineering Contradiction:
Improvehardware resource utilizationVSAvoidnetwork access control management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized control plane as an intermediary component that manages network access control for multiple virtual machines. This control plane sits between the virtual machines and the physical network infrastructure, handling authentication, authorization, and policy enforcement centrally, thereby simplifying management while enabling high-density VM deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments network access control functions into separate modular components including a control plane for policy management, data planes for packet forwarding, and authentication services. This segmentation allows independent management of control logic from data forwarding, reducing overall system complexity while supporting multiple VMs.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If a centralized control plane is implemented to simplify network access control management, then management complexity is reduced, but system architecture complexity increases

Engineering Contradiction:
Improvenetwork access control management easeVSAvoidsystem architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The centralized control plane is designed as a universal management entity that handles multiple functions including authentication, authorization, accounting, and policy enforcement through a single interface. This multi-functional design simplifies operations by providing unified management while the modular internal architecture prevents excessive complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The control plane implements feedback mechanisms where data plane components report status and events back to the control plane, which then adjusts policies and configurations accordingly. This automated feedback loop reduces manual management complexity while the standardized feedback protocols prevent architecture from becoming overly complex.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2318923B1Centralized control plane appliance for a virtual infrastructure
Publication Date: 2020.07.15 CISCO TECHNOLOGY INC
  • EP2318923B1 patent drawingFigure 1
  • EP2318923B1 patent drawingFigure 2

AI summary

In a virtual infrastructure, a single appliance (12, 36) is provided that hosts a centralized virtual machine monitor (VMM) control plane (34) to effectively establish a single virtual switch across all virtual machines (18) within one or more clusters of servers (12), thereby reducing the number of management points for the network administrator and facilitating easier VM migration.